11-17-2014 09:38 PM - edited 03-10-2019 10:11 PM
Is it possible to use ISE(inline posture node) to redirect the wired users to ISE guest portal ?
And the wired users will get full network access after they pass the web auth.
Solved! Go to Solution.
11-18-2014 03:18 AM
Hello,
It could theorically work if the switch is able to send all attributes in accounting packets, such as IP address and mac address in calling station-id. If the attributes are missing or incorrect, the iPEP ISE will never create the session (see show pep table session).
Being that said, that probably never have been tested, so you might want to reconsider your design as there are no guarantee this can ever work.
11-18-2014 03:18 AM
Hello,
It could theorically work if the switch is able to send all attributes in accounting packets, such as IP address and mac address in calling station-id. If the attributes are missing or incorrect, the iPEP ISE will never create the session (see show pep table session).
Being that said, that probably never have been tested, so you might want to reconsider your design as there are no guarantee this can ever work.
11-21-2014 05:48 AM
you can use ISE ln-line posture node with 3rd part switches
RADIUS access device must supply the following RADIUS attributes:
Calling-Station-Id (for MAC_ADDRESS)
User-Name
NAS-Port-Type
RADIUS accounting message must have the Framed-IP-Address attribute
VLAN, DACL features can be used but again it depends on switch models let us know specific switch models . Certain advanced use cases, such as those that involve posture assessment, profiling, and web authentication, are not consistently available with non-Cisco devices or may provide limited functionality,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide